CVE-2009-0802
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.
Qbik WinGate, cuando el modo de intercepción transparente esta activado, utiliza una cabecera de Host HTTP para determinar un punto final remoto, lo que permite a atacantes remotos evitar el control de acceso para Flash, Java, Silverlight y probablemente otras tecnologías, y posiblemente comunicar con sitios restringidos de redes internas a través de una pagina web manipulada que causa que el cliente envíe peticiones HTTP con una cabecera host modificada.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-03-04 CVE Reserved
- 2009-03-04 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.kb.cert.org/vuls/id/435052 | Third Party Advisory | |
http://www.securityfocus.com/bid/33858 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.0.0 Search vendor "Qbik" for product "Wingate" and version "6.0.0" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.0.1_build_993 Search vendor "Qbik" for product "Wingate" and version "6.0.1_build_993" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.0.1_build_995 Search vendor "Qbik" for product "Wingate" and version "6.0.1_build_995" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.0.2_build_1000 Search vendor "Qbik" for product "Wingate" and version "6.0.2_build_1000" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.0.2_build_1001 Search vendor "Qbik" for product "Wingate" and version "6.0.2_build_1001" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.0.3_build_1005 Search vendor "Qbik" for product "Wingate" and version "6.0.3_build_1005" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.1 Search vendor "Qbik" for product "Wingate" and version "6.1" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.1.1.1077 Search vendor "Qbik" for product "Wingate" and version "6.1.1.1077" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.1.2 Search vendor "Qbik" for product "Wingate" and version "6.1.2" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.1.3 Search vendor "Qbik" for product "Wingate" and version "6.1.3" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.1.4 Search vendor "Qbik" for product "Wingate" and version "6.1.4" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.2 Search vendor "Qbik" for product "Wingate" and version "6.2" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.2.1 Search vendor "Qbik" for product "Wingate" and version "6.2.1" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.2.2 Search vendor "Qbik" for product "Wingate" and version "6.2.2" | - |
Affected
| ||||||
Qbik Search vendor "Qbik" | Wingate Search vendor "Qbik" for product "Wingate" | 6.5.2 Search vendor "Qbik" for product "Wingate" and version "6.5.2" | - |
Affected
|